Количество 36
Количество 36
CVE-2026-6472
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6472
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6472
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
CVE-2026-6472
PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
CVE-2026-6472
Missing authorization in PostgreSQL CREATE TYPE allows an object creat ...
GHSA-3276-f9jg-jf2x
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
BDU:2026-07103
Уязвимость команды CREATE TYPE системы управления базами данных PostgreSQL, позволяющая нарушителю выполнять произвольные SQL-функции
ROS-20260706-73-0015
Уязвимость postgresql15
ROS-20260706-73-0014
Уязвимость postgresql14
ROS-20260706-73-0013
Уязвимость postgresql18-1c
ROS-20260706-73-0012
Уязвимость postgresql17-1c
ROS-20260706-73-0011
Уязвимость postgresql15-1c
ROS-20260706-73-0010
Уязвимость postgresql-1c
ROS-20260706-73-0009
Уязвимость postgresql17
ROS-20260706-73-0008
Уязвимость postgresql16
ROS-20260706-73-0007
Уязвимость postgresql18
openSUSE-SU-2026:21103-1
Security update for postgresql15
openSUSE-SU-2026:21102-1
Security update for postgresql14
SUSE-SU-2026:2117-1
Security update for postgresql14
SUSE-SU-2026:2086-1
Security update for postgresql14
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6472 Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6472 Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6472 Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6472 PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6472 Missing authorization in PostgreSQL CREATE TYPE allows an object creat ... | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-3276-f9jg-jf2x Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That is to say, the victim will execute arbitrary SQL functions of the attacker's choice. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
BDU:2026-07103 Уязвимость команды CREATE TYPE системы управления базами данных PostgreSQL, позволяющая нарушителю выполнять произвольные SQL-функции | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
ROS-20260706-73-0015 Уязвимость postgresql15 | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0014 Уязвимость postgresql14 | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0013 Уязвимость postgresql18-1c | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0012 Уязвимость postgresql17-1c | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0011 Уязвимость postgresql15-1c | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0010 Уязвимость postgresql-1c | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0009 Уязвимость postgresql17 | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0008 Уязвимость postgresql16 | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
ROS-20260706-73-0007 Уязвимость postgresql18 | CVSS3: 5.4 | 0% Низкий | 25 дней назад | |
openSUSE-SU-2026:21103-1 Security update for postgresql15 | около 1 месяца назад | |||
openSUSE-SU-2026:21102-1 Security update for postgresql14 | около 1 месяца назад | |||
SUSE-SU-2026:2117-1 Security update for postgresql14 | 2 месяца назад | |||
SUSE-SU-2026:2086-1 Security update for postgresql14 | 2 месяца назад |
Уязвимостей на страницу